cOndemned
40 exploits
Active since Mar 2008
Z-Breaknews 2.0 - SQL Injection via id Parameter
xlportal < 2.2.4 - SQL Injection via Query Parameter
txtBB 1.0 RC3 - HTML/JS Injection / Arbitrary Add Admin Privileges
TinyCMS 1.1.2 - Remote File Inclusion via ZZ_Templater config[template] Parameter
TaskDriver < 1.3 - Unauthenticated Authentication Bypass via Auth Cookie
txtCMS 0.3 - Path Traversal via ID Parameter
SquareCMS 0.3.1 - 'post.php' SQL Injection
riotpix < 0.61 - SQL Injection via ForumID Parameter
phsblog 0.1.1 - SQL Injection via eid, cid, or urltitle Parameter
phpTest 0.6.3 - SQL Injection via image_id Parameter
PHPhotoalbum 0.5 - SQL Injection via Album or PID Parameter
PhotoDiary 1.3 - 'lng' Local File Inclusion
OvBB 0.16a - Multiple Local File Inclusions
MyioSoft AjaxPortal 3.0 - SQL Injection via Page Parameter
My Simple Forum <4.1 - Path Traversal
MyTopix < 1.3.0 - Authenticated SQL Injection via Notes Action Send Parameter
MxBB Portal 2.7.3 - SQL Injection via Page Parameter
LoveCMS 1.6.2 Final - Multiple Local File Inclusions
LokiCMS <= 0.3.3 - Unauthenticated Arbitrary File Deletion via Admin.php Delete Parameter
LoveCMS 1.6.2 Final - Unauthenticated Arbitrary File Upload via Download Manager
LoveCMS The Simple Forum 3.1d - Unauthenticated Administrator Password Change via Direct Request
LoveCMS 1.6.2 Final - Path Traversal
Mini Blog 1.0.1 - Path Traversal via Page and Admin Parameters
Mini CMS 1.0.1 - Remote File Inclusion via Page and Admin Parameters
Kensei Board < 2.0.0b - SQL Injection via f and t Parameters